The FBI has removed an Accenture contractor after an internal review found that a missed security patch led to a ShinyHunters breach that exposed personal details of thousands of bureau employees. The statement, attributed to FBI cyber division assistant director Brett Leatherman, said the incident stemmed from a security failure in a platform managed by a third-party organization.
The FBI did not name the third party, but Reuters reported it was Oracle PeopleSoft, the system behind the FBI's job portal that ShinyHunters claimed to have breached last month. Mandiant assessed that the group exploited a bypass for CVE-2026-35273, using a URL-encoding trick to evade a web application firewall rule meant to block the vulnerable Environment Management Hub endpoint.
Accenture said it remains proud to support the FBI's mission. The breach is the latest in ShinyHunters' operational history; two members have been arrested, and the FBI says it is working with partners to execute more leads and expects further arrests.